VIDEO: BSA SAR Continuing Activity Reviews

VIDEO: BSA SAR Continuing Activity Reviews

In this Compliance Clip (video), Adam discusses FinCEN’s October 2025 FAQ addressing continuing activity reviews after a suspicious activity report (SAR) has been filed. He explains why this clarification has raised questions for financial institutions and explores what BSA/AML/CFT teams should consider when monitoring for continued suspicious activity.


Video Transcript

The following is a transcript of this video.

This Compliance Clip is going to talk about continuing activity reviews for suspicious activity reports. This is a BSA/AML/CFT topic.

This is a question that has stemmed from the FinCEN Frequently Asked Questions set that came from October 2025. The question says this: Is a financial institution required to conduct a review of a customer or account following the filing of a suspicious activity report to determine whether suspicious activity has continued since the last filing?

Again, this was part of the set of Frequently Asked Questions that was released by FinCEN in October 2025 that raised a lot of eyebrows because the answer to this question, typically, we've thought of as yes, of course we have to continue to monitor for suspicious activity after a SAR has been filed. And the answer to this from FinCEN is technically no. They explain it, so let's read through some of what they said in this frequently asked question to have a better understanding, and we'll discuss this in a minute.

They say, “No, a financial institution is not required to conduct a separate review, manual or otherwise, of a customer or account following the filing of a SAR to determine whether suspicious activity has continued since the last SAR filing.” They say that recognizing the burden that continued SAR filings on the same customer or account places on financial institutions, FinCEN suggested way back in October 2000 that institutions file a SAR for repeated and ongoing suspicious activity at

least every 90 days. So you don't have to file it every time a continuing activity of the same type occurs. If it occurs weekly, you don't have to file weekly reports. You can, once the initial one's been filed, you can do it at least every 90 days.

They go on to explain that over time, this suggestion has become interpreted, probably by examiners and auditors, as a requirement or expectation that financial institutions conduct a separate review of a customer or account following the filing of a SAR to determine whether suspicious activity has, in fact, continued or not. Now, what they say is that's not required. Financial institutions instead may rely on risk-based internal policies, procedures, and controls to monitor and report suspicious activity as appropriate, provided those internal policies, procedures, and controls are reasonably designed to identify and report such activity.

So, what does this mean?

Well, for those of you that have BSA/AML software that you utilize, your software would probably detect every time suspicious activity occurs, whether or not it was part of continuing activity or new activity. So that's the whole point here: if you've got procedures designed to be picking up suspicious activity, you're probably already picking it up, and you don't have to conduct a separate review just because 90 days has passed. So that's what they're saying.

Now, for smaller financial institutions, those of you that are small banks or small credit unions that may not have BSA/AML software, you may have a manual system and the question is, is that manual system reasonably designed to pick up your suspicious activity? The answer is probably yes. But some of you have designed your systems to make sure that you are, in fact, re-reviewing suspicious activity reports that have been filed to see if there has been continuing activity. So, when you have more of a manual process, I think it's more important to have this standalone review again, depending on how you've designed it.

Here, FinCEN is clarifying that a separate review of continuing activity is not technically required under FinCEN's rules or under the Bank Secrecy Act itself. Therefore, if you have systems in place that would be picking up suspicious activity, you don't have to conduct a separate review.

Now, logistically, how you manage that, that's the key piece. That I can't answer for you in this Compliance Clip, but that, of course, is the key piece to making sure you don't have problems in either your audits or your exams. That is something you want to make sure is working properly. Otherwise, that continuing activity review, if you're still doing, that might be an important piece of your existing policies and procedures to prevent and detect suspicious activity from occurring in your financial institution.

That's all I have for this Compliance Clip.

Fair Lending Bootcamp On Sale!